<remote> <connection>syslog</connection> <port>514</port> <local_ip>x.x.x.x</local_ip> <protocol>udp</protocol> <allowed-ips>x.x.0.x/24</allowed-ips> <allowed-ips>x.x.1.x/24</allowed-ips> <allowed-ips>x.x.x.x</allowed-ips> </remote>
udp UNCONN 0 0 <local_ip>:514 *:* users:(("ossec-remoted",pid=26362,fd=4))udp UNCONN 0 0 <local_ip>:1514 *:* users:(("ossec-remoted",pid=26363,fd=4))
strace -p 26362Process 26362 attached
recvfrom(4, "<134>Mar 10 12:23:04 filterlog: "..., 1024, 0, {sa_family=AF_INET, sin_port=htons(514), sin_addr=inet_addr("x.x.x.202")}, [16]) = 157stat("/queue/ossec/.wait", 0x7fff574957a0) = -1 ENOENT (No such file or directory)sendto(5, "2:x.x.x.202:Mar 10 12:23:04 fil"..., 166, 0, NULL, 0) = 166recvfrom(4, "<134>Mar 10 12:23:04 filterlog: "..., 1024, 0, {sa_family=AF_INET, sin_port=htons(514), sin_addr=inet_addr("x.x.x.202")}, [16]) = 157stat("/queue/ossec/.wait", 0x7fff574957a0) = -1 ENOENT (No such file or directory)sendto(5, "2:x.x.x.202:Mar 10 12:23:04 fil"..., 166, 0, NULL, 0) = 166recvfrom(4, "<134>Mar 10 12:23:04 filterlog: "..., 1024, 0, {sa_family=AF_INET, sin_port=htons(514), sin_addr=inet_addr("x.x.x.254")}, [16]) = 158stat("/queue/ossec/.wait", 0x7fff574957a0) = -1 ENOENT (No such file or directory)
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/01d1b388-f924-4c37-805f-0898ad0f5924%40googlegroups.com.--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.